logo

How we take down malicious Visual Studio Code extensions

ID: f7daa5a6-3458-52e4-b436-8075f8c4491b

STIX ID: report--f7daa5a6-3458-52e4-b436-8075f8c4491b

Feed Name: Checkmarx Zero

Threat Score
60/100

Date Published: 2025-11-13

Date Updated: 2026-04-27

Author: Daniel Miranda

...
...

Checkmarx Zero identified and disclosed three malicious VS Code extensions (automatedlogic.automatedlogic, automated1ogic.automated1ogic, webctrl.live) published May 2024 that typosquatted the Automated Logic/WebCTRL brand; the extensions auto-activated, collected host metadata and exfiltrated it to hard-coded HTTP endpoints (IPs: 45.76.218.40:61031 and 45.76.218.40:10442), and one contained a commented downloader capable of fetching and executing remote payloads; Microsoft removed the extensions after reporting in September 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.